Re: [PATCH 4.19-stable 4/5] spi: bcm2835aux: Fix use-after-free on unbind

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On Mon, Dec 07, 2020 at 05:49:01PM -0700, Nathan Chancellor wrote:
> On Sun, Dec 06, 2020 at 01:31:03PM +0100, Lukas Wunner wrote:
> > [ Upstream commit e13ee6cc4781edaf8c7321bee19217e3702ed481 ]
> > 
> > bcm2835aux_spi_remove() accesses the driver's private data after calling
> > spi_unregister_master() even though that function releases the last
> > reference on the spi_master and thereby frees the private data.
> > 
> > Fix by switching over to the new devm_spi_alloc_master() helper which
> > keeps the private data accessible until the driver has unbound.
> > 
> > Fixes: b9dd3f6d4172 ("spi: bcm2835aux: Fix controller unregister order")
> > Signed-off-by: Lukas Wunner <lukas@xxxxxxxxx>
> > Cc: <stable@xxxxxxxxxxxxxxx> # v4.4+: 5e844cc37a5c: spi: Introduce device-managed SPI controller allocation
> > Cc: <stable@xxxxxxxxxxxxxxx> # v4.4+: b9dd3f6d4172: spi: bcm2835aux: Fix controller unregister order
> > Cc: <stable@xxxxxxxxxxxxxxx> # v4.4+
> > Link: https://lore.kernel.org/r/b290b06357d0c0bdee9cecc539b840a90630f101.1605121038.git.lukas@xxxxxxxxx
> > Signed-off-by: Mark Brown <broonie@xxxxxxxxxx>
> 
> Please ensure that commit d853b3406903 ("spi: bcm2835aux: Restore err
> assignment in bcm2835aux_spi_probe") is picked up with this patch in all
> of the stable trees that it is applied to.

That shouldn't be necessary as I've made sure that the backports to
4.19 and earlier do not exhibit the issue fixed by d853b3406903.

However, nobody is perfect, so if I've missed anything, please let
me know.

Thanks!

Lukas



[Index of Archives]     [Linux Kernel]     [Kernel Development Newbies]     [Linux USB Devel]     [Video for Linux]     [Linux Audio Users]     [Yosemite Hiking]     [Linux Kernel]     [Linux SCSI]

  Powered by Linux